Cloud Firewalls (beta) questions
I’m eagerly awaiting the release of the Cloud Firewalls to the London DC 😊
In the meantime, does anyone know if it protects the private network IP, and an IPv6 /64 range?
Can you assign inbound rules separately to the destination IPs? For example, I might want to open a port on the public IPv4, but not on all addresses in the IPv6 range.
Also will it work with the upcoming VLAN functionality, or does it only protect traffic coming in from the public net, whereas VLAN is internal to the DC?
4 Replies
Hey @andysh - I checked in with our Cloud Firewalls team about this to get a little clarification, and here are the answers they sent your way:
Do we have a timeline for when Cloud Firewalls will be available in London?
This should be happening very, very soon. Keep your eyes on our blog for an official announcement.
Does it protect the private network IP, and an IPv6 /64 range?
Yes. You can firewall off private IPs and it functions with IPv6 ranges.
Can you assign inbound rules separately to the destination IPs? For example, opening a port on the public IPv4, but not on all addresses in the IPv6 range.
You should be able to pull this off by creating two firewall rules (order matters). You can have the port open on IPv4 CIDR all and "allow" as the first rule. The other rule would come after for the same port and set IPv6 CIDR to "drop".
Will it work with the upcoming VLAN functionality, or does it only protect traffic coming in from the public net, whereas VLAN is internal to the DC?
Yup! It should work for VLAN traffic.
If you want to try things out in the meantime, Cloud Firewalls will work for any Linodes you have in the Toronto, Mumbai, and Sydney data centers.
I may be a bit premature as I’ve not seen an announcement but Cloud Firewalls are now live in London.
I was browsing round the Linode website earlier and saw that London was listed as a “now available” location on the firewalls page.
I checked in Manager and lo and behold my London Linodes are now listed in the firewall section, and I’ve deployed a firewall to them this evening.
Happy days :)